site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
6327
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2
AuthorAll Replies


2kmaro
Think
Premium,ExMod 1 BC
join:2000-07-11
ColossalCave

Patch for ZoneAlarm Mutex Problem!

DiamondCS has published a patch to help overcome the mutex vulnerability of ZoneAlarm and ZoneAlarm Pro. This is the problem where ZA/ZAP can be shut down and not restarted! I've applied the patch and tested it against their program that shows the problem. (NOTE: after applying the patch, when you run the test it will still say that ZA/ZAP is shut down and cannot restart, but if you go to your system tray you'll find ZA/ZAP fully functional.)

Here is text from DiamondCS and a link to the patch.
----------
Subject: Patch now available to protect against conventional mutex hijacking
of ZoneAlarm/ZoneAlarm Pro

DiamondCS ZA Mutex Patch

This patch re-hashes the Zone Alarm mutex in both ZoneAlarm and ZoneAlarm Pro. It is a temporary "band-aid" patch, and as such it is not bulletproof and it is possible that it could be undone. However, it still greatly improves the local security of ZoneAlarm regarding this situation - it's mutex (as demonstrated by zonemutx.exe) can no longer be conventionally hijacked. The real solution to this problem can only be implemented by Zone Labs, but until then hopefully this "band-aid" will last. "Some security is better than no security!"

To apply the patch:
Download and run zamutex.exe (and needless to say, make sure you properly shut down ZoneAlarm before running the patch) - it will ask you where the ZoneAlarm.exe/ZAPro.exe file you want to patch is located. Select the file, press OK and the program will do the rest by safely patching that file and it's accompanying zoneband.dll file.

As with all patches, it is recommended that you make a backup of the files (zoneband.dll and Zonealarm.exe/zapro.exe) before applying the patch.

Best regards,
Wayne / DiamondCS
---------

--
The only virus on my computer is Windows.


JANDOENT

join:2000-10-05
Tampa, FL

Hey 2K, We must have been writing it at the same time as I didn't see your thread until after I had posted mine! After I installed it, I did a re boot as I always do, and ZA reloaded on startup with out any error messages.
I received an email from a reader here. I invited him to come and join our forum. I didn't know if maybe he had emailed you as well.
--
Inquiring minds want to know...



2kmaro
Think
Premium,ExMod 1 BC
join:2000-07-11
ColossalCave

I received my email from Wayne at DiamondCS - if I'd stayed up a little longer last night, we would have been WAY ahead of GRC!! Thanks again for allowing the threads to get pointed to the same place.


GaryK7
Premium
join:2000-08-29
Miami, FL
Reviews:
·Atlantic Broadband

reply to 2kmaro
I wonder what ZoneLabs' official position will be on the patch? If you install it will ZL no longer give you technical support?

I'll be sure to include this new information and a link to the patch on the website we should be putting into production later today, 2k.

Thanks.
--
-tb/gary.
"The person who says it cannot be done should not interrupt the person doing it."
Chinese Proverb



2kmaro
Think
Premium,ExMod 1 BC
join:2000-07-11
ColossalCave

So, who's going to tell them they put the patch in?;)



dainbramage
I'M Just Not That Into Me
Premium
join:2000-09-02
Lynn, MA

reply to 2kmaro
Once again, thank you 2k, for the info. I downloaded and installed the patch, everything is working fine.



jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
Scottsdale, AZ
kudos:19
Reviews:
·Speakeasy

reply to 2kmaro
Just out of curiosity, will the patch create any problems down the line when an updated version comes out?
--
JKK

Age is a very high price to pay for my maturity, so
if I can't stay young, I can at least stay immature!



2kmaro
Think
Premium,ExMod 1 BC
join:2000-07-11
ColossalCave

I would expect that it may not be compatible with a newer version - hopefully, since ZA indicates that the next version is some months down the road, they will have incorporated SOME kind of fix into their system. The patch, as I understand it, is specifically for basic ZoneAlarm 2.1.44 or ZoneAlarm Pro 1.0.



JANDOENT

join:2000-10-05
Tampa, FL

We all should have and are allowed to have a back up copy...
--
Inquiring minds want to know...



jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
Scottsdale, AZ
kudos:19
Reviews:
·Speakeasy

Good standard practice for all things downloaded, IMO. I have all the exe. files of my programs on my zip drive, just incase I should ever need to reinstall something. If I don't have a back up on my zip drive, I have the original CD. Never care to be caught with my pants down, as it were.

***No comments, Pope Poitin!
--
JKK

Age is a very high price to pay for my maturity, so
if I can't stay young, I can at least stay immature!


GaryK7
Premium
join:2000-08-29
Miami, FL
Reviews:
·Atlantic Broadband

reply to 2kmaro

said by 2kmaro:
I received my email from Wayne at DiamondCS - if I'd stayed up a little longer last night, we would have been WAY ahead of GRC!! Thanks again for allowing the threads to get pointed to the same place.
If you had stayed up any later last night it would have been morning. Thanks for all your hard work on this issue. Here's one vote for you!
--
-tb/gary.
"The person who says it cannot be done should not interrupt the person doing it."
Chinese Proverb


Gizmo
Who me? I live here.
Premium,MVM
join:2000-08-19
Funny Farm
kudos:1
Reviews:
·AT&T Southeast

reply to 2kmaro
Thanks 2k for the information and the link to the patch!!:)
--
~gizmo

Can ya spare some unused cpu cycles?
Join Folding@Home, DSL Reports Team Helix
"One small step for man, one giant leap for mankind" - Neil Armstrong



Wildcatboy
Premium,Mod
join:2000-10-30
Toronto, ON
kudos:2

reply to 2kmaro

As always, good job 2kmaro. I'm wondering if this would be enough to shame ZL. It's funny when someone else can fix their product better than they can.
--
You can catch the Devil, but you can't hold him long.



jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
Scottsdale, AZ
kudos:19
Reviews:
·Speakeasy

said by Wildcatboy:

As always, good job 2kmaro. I'm wondering if this would be enough to shame ZL.
I would be willing to take a wager on that one, though it is an no-brainer in my opinion and should happen. My bet is that it won't though. The attitude of the higher ups in ZL seemed to scream that that would be something far from their thoughts. They had the opportunity to have done the job themselves before, and with the attitude that they portrayed, my guess is that they'll just pretend they never saw the patch nor had it suggested to them to do it themselves.
--
JKK

Age is a very high price to pay for my maturity, so
if I can't stay young, I can at least stay immature!


korupt

join:2000-03-18
Canada
Reviews:
·Shaw

reply to 2kmaro
Thanks 2k,got the patch and installed without problem. ZA should be ashamed that another company has fixed the problem. Or was it that ZA was to lazy to make the required changes and hoped that some "white knight" would come along and save their sorry a$$. :D



Rocktagon
Slightly Bent
Premium
join:2000-11-04
Chattaroy, WA

reply to 2kmaro
Just want to add another GOOD JOB !!
Sure am glad to be a member here and stay on top of important issues such as this.


--
Quest for Knowledge



EmilioG
Whats This?
Premium
join:2000-09-19
New York, NY

Man, that was really great of Wayne from diamondCS to provide this patch for us. I've never seen another company do this. I'm going to write a thank you note to Wayne Langlois of DiamondCS, way to go Wayne!

MODERATOR NOTE: Wayne Langlois has requested that you NOT send him emails thanking him - he is getting covered up with email and cannot get on with his regular job.

[text was edited by author 2001-01-03 22:04:05]

[text was edited by moderator]

[text was edited by author 2001-01-04 19:48:12]



paul613

join:2000-04-19
College Park, MD

reply to 2kmaro
I don't see that patch linked PUBLISHED on their site anywhere, could you provide the link to the page that you found it on. I would like to read the info they provided prior to download.

IT seems after applying the patch(for me at least) the patch seems ok and ZA runs. BUT HAS LOST THE ABLITIY to update/upgrade itself, it responds with "Unable to identify the version". I want to know if Diamond published the LOSS of some functionality, and if so what else the PATCH prevents the program from doing.

Anyone else LOSE the ablity for zone alarm to update itself or even check for updates?
--
Don't take life too seriously, you will never get out alive!


GaryK7
Premium
join:2000-08-29
Miami, FL
Reviews:
·Atlantic Broadband

reply to EmilioG
That's a great idea, Emilio.

BTW, I am unofficially announcing the launch of a website that presents information and links to information about the ZA problem. You can also send a complaint e-mail to ZoneLabs by just filling in a few form fields and clicking a button.

ZoneAlarm Alarm

If it survives its beta test this evening I'll post a message about it in this forum tomorrow.

Many thanks to 2kmaro for providing much of the site's content. The graphics and coding are mine.
--
-tb/gary.
"The person who says it cannot be done should not interrupt the person doing it."
Chinese Proverb
---
Angry at ZoneAlarm? Complain about it!



paul613

join:2000-04-19
College Park, MD

sure hope you got permission to use there copyright protected logos on that site!

--
Don't take life too seriously, you will never get out alive!


Sunday, 03-Jun 11:22:27 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics